A newly uncovered software supply chain attack has shown how quickly a trusted developer account can become a delivery route for malware. The operation, tracked as GHAPPIER, reached 65 GitHub repositories, infecting 73 files across 22 accounts. It involved a legitimate npm package that distributed a malicious loader to users. Attackers used access to a package maintainer account to alter source code and automate publication from the project’s main branch. The poisoned release appeared legitimate because it was built through the project’s automated publishing process. That made a routine dependency update capable of carrying a remote code loader into developer environments. CloudSEK said in a report shared with Cyber...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!